CVE-2026-84663: CSRF
Published Sep 2, 2026
·Updated
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.
Affected Software
1 affected component
Jenkins Jenkins Pipeline: Groovy Libraries Plugin<=798.v5cc688825312
Event History
Sep 2, 2026
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
Description
Frequently Asked Questions
1
What does an attacker need to do to exploit this issue?
An attacker needs to cause a victim to submit a cross-site request to Jenkins. Successful exploitation can delete shared library caches.
2
Which plugin versions are affected?
Jenkins Pipeline: Groovy Libraries Plugin version 798.v5cc688825312 and earlier is affected.